digline command protection
Reviews digline commands that spend model calls, write under .digline/, or can promote a baseline.
Reviews digline commands that spend model calls, write under .digline/, or expose a way to change the approved baseline. digline is a regression gate for LLM applications, the approved reference lives in your repo.
command.digline · v1.0.0 · Other extensions
- Protection rules
- 6
- Permission checks
- 6
- Mapped commands
- 6
Overview
What this coverage does
Reviews digline commands that spend model calls, write under .digline/, or expose a way to change the approved baseline. digline is a regression gate for LLM applications, the approved reference lives in your repo.
Key facts
- Catalog ID
command.digline- Version
- v1.0.0
- Kind
- Command coverage
- Category
- Other extensions
- Protection rules
- 6
- Permission checks
- 6
- Mapped commands
- 6
- Maintainer
- Community contributor(community, provenance recorded)
- Source commit
- 3b129e0
- Protection model
- External · opt-in
External coverage. It must be enabled through Guard controls; this page does not activate it.
Stated limits
- Coverage matches digline subcommand names; it does not resolve arguments as paths under .digline/.
- A maintainer profile is not a security certification or an official upstream endorsement.
diglinellmevaluationregressioncliCommand mapping
Every command this extension recognizes, with the catalog default floor Guard applies before workspace policy. Search the table, then open an operation for safe variants and the permission ID.
6 operations · 6 reviewed by default These are catalog defaults, not your workspace policy.
Showing 6 of 6 operations
- Reviewed Guard intercepts the command for review before it runs.High
digline migrate
digline store migration
- Default floor
- Reviewed by default. Guard intercepts the command for review before it runs.
- Detector mode
- review
- What it matches
- Identifies `digline migrate`, which rewrites stored runs and the baseline under .digline/ to the current schema.
- Documented safe variants
digline migrate dry rundigline migrate command helpskip this operation when they are the documented preview or help form.- Permission ID
- command.digline.permission.migrate
- Reviewed Guard intercepts the command for review before it runs.High
digline promote
digline baseline promotion
- Default floor
- Reviewed by default. Guard intercepts the command for review before it runs.
- Detector mode
- review
- What it matches
- Identifies `digline promote`, which makes a stored run the approved baseline under .digline/, replacing the reference every later comparison is gated against.
- Documented safe variants
digline promote command helpskip this operation when they are the documented preview or help form.- Permission ID
- command.digline.permission.promote
- Reviewed Guard intercepts the command for review before it runs.High
digline register
digline disposition record
- Default floor
- Reviewed by default. Guard intercepts the command for review before it runs.
- Detector mode
- review
- What it matches
- Identifies `digline register`, which records a person's disposition about a comparison under .digline/; an agent running it records a decision that belongs to a person.
- Documented safe variants
digline register command helpskip this operation when they are the documented preview or help form.- Permission ID
- command.digline.permission.register
- Reviewed Guard intercepts the command for review before it runs.High
digline view
digline review UI
- Default floor
- Reviewed by default. Guard intercepts the command for review before it runs.
- Detector mode
- review
- What it matches
- Identifies `digline view`, which serves a local web UI over the stored runs. The UI exposes a promote action, so the command can change the approved baseline under .digline/ even though it writes nothing by itself.
- Documented safe variants
digline view command helpskip this operation when they are the documented preview or help form.- Permission ID
- command.digline.permission.view
- Reviewed Guard intercepts the command for review before it runs.Medium
digline rejudge
digline rejudge
- Default floor
- Reviewed by default. Guard intercepts the command for review before it runs.
- Detector mode
- review
- What it matches
- Identifies `digline rejudge`, which calls the judge again on a stored run's recorded answers, spends judge calls, and writes a new run under .digline/.
- Documented safe variants
digline rejudge command helpskip this operation when they are the documented preview or help form.- Permission ID
- command.digline.permission.rejudge
- Reviewed Guard intercepts the command for review before it runs.Medium
digline run
digline suite run
- Default floor
- Reviewed by default. Guard intercepts the command for review before it runs.
- Detector mode
- review
- What it matches
- Identifies `digline run`, which executes the suite against the target, spends model and judge calls, and writes a new run under .digline/.
- Documented safe variants
digline run command helpskip this operation when they are the documented preview or help form.- Permission ID
- command.digline.permission.run
Tool state mapping
No per-tool overrides are declared. Command defaults above resolve through the workspace Guard policy unless a later policy layer changes them.
Runtime identity
- Catalog ID
- command.digline
- Guard enforcement ID
- command.digline
- Source path
- contributions/extensions/command.digline.json
- Contribution digest
sha256…fdab0a
Action classes
digline suite run commanddigline rejudge commanddigline baseline promotion commanddigline disposition record commanddigline store migration commanddigline review UI commandTechnical profile
No independent profile published
This extension has no current independent technical profile. Catalog facts and any legacy launch remain separate and are not presented as profile evidence.
FAQ
Frequently asked questions
Reviews digline commands that spend model calls, write under .digline/, or expose a way to change the approved baseline. digline is a regression gate for LLM applications, the approved reference lives in your repo. The listing declares 6 rules and 6 permission checks. 6 operations · 6 reviewed by default. Coverage is limited to these reviewed operations and the surrounding Guard policy.
External · opt-in: External coverage. It must be enabled through Guard controls; this page does not activate it. Enabling state is always controlled through Guard policy, never from this directory.
This listing entered the catalog as a community contribution through a public pull request with recorded provenance, with public credit to @alexpran, and 1 GitHub maintainer is recorded on the listing. Credit is attribution only. A verified publisher profile and the claim flow verify authority separately; neither is an upstream endorsement or a HOL safety certification.
No. Every listing documents source, activation model, maintainer identity, and stated limitations so you can evaluate coverage before enabling it. Review the stated limitations and the exact source tree before relying on any single control.
6 operations · 6 reviewed by default. Examples: digline migrate (reviewed by default); digline promote (reviewed by default); digline register (reviewed by default); digline view (reviewed by default); digline rejudge (reviewed by default); digline run (reviewed by default). These are catalog defaults, not your workspace policy.
External coverage. It must be enabled through Guard controls; this page does not activate it. Enablement is managed through your workspace's Guard policy and controls — never from this directory. Open the install guidance for the setup flow, then adjust the command coverage for command.digline in Guard's policy surface.
The matching action is stopped at Guard's pre-action boundary before it executes, and the decision is recorded with evidence your workspace can review. Exact behavior follows your Guard policy combined with this entry's 6 rules and 6 permission checks.
No. Guard is local-first: interception, decisions, and evidence stay on your machine unless your workspace explicitly configures cloud features. This page is documentation only — it never executes a command or changes protection state.
Guard runs locally alongside the major AI coding agents and MCP-capable harnesses, so this coverage applies wherever Guard intercepts actions. See the supported harness guides at https://hol.org/guard/harnesses for per-tool approval behavior and limitations.
Guard has a free local tier that includes command interception, evidence, and the policy controls this listing documents. Team plans add shared policy, review queues, and audit surfaces. Current plans: https://hol.org/guard/pricing
Open an issue or pull request against the hol-guard repository, where the canonical catalog lives: https://github.com/hashgraph-online/hol-guard Listings are corrected through the same public review process that adds them.
Yes. Community extensions are merged through public pull requests with recorded provenance, and you can claim the publisher page for a contribution you maintain through the Publisher Studio.
The command mapping table is the audit trail for covered commands and catalog default floors. Pair it with the reviewed rule and permission counts, the per-tool state mapping, and the exact source tree linked from View exact source at the reviewed commit. Guard records enforcement decisions with evidence locally, so what ships matches what you reviewed.